CVE-2023-21608highunder attackCWE-416

CVE-2023-21608: high-severity vulnerability in Adobe Acrobat Reader

Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability

Published · Updated

88Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 61%
from disclosure to weapon12 days
Published on NVDJan 18
1st PoC+12d
CISA KEV+265d
exploitation probability
61%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
4 public exploit(s)
Action required by CISAfederal deadline: 2023-10-31

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

Adobe Acrobat Reader has a flaw where it tries to use data that has already been freed from memory when handling PDF forms. An attacker can exploit this by sending a malicious PDF file that, when opened, allows them to run code on the victim's computer.

Technical detail

Use-after-free vulnerability in Adobe Acrobat Reader's resetForm function allows remote code execution with user context privileges. Attack vector requires user interaction (opening a malicious PDF file); no authentication or special privileges are needed. Affected versions include 22.003.20282 and earlier, 22.003.20281 and earlier, and 20.005.30418 and earlier.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Adobe · Acrobat Reader
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.